CVE-2019-15990

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
26/11/2019
Last modified:
16/10/2020

Description

A vulnerability in the web-based management interface of certain Cisco Small Business RV Series Routers could allow an unauthenticated, remote attacker to view information displayed in the web-based management interface. The vulnerability is due to improper authorization of HTTP requests. An attacker could exploit this vulnerability by sending crafted HTTP requests to the web-based management interface of an affected device. A successful exploit could allow the attacker to view information displayed in the web-based management interface without authentication.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:cisco:rv016_multi-wan_vpn_firmware:*:*:*:*:*:*:*:* 4.2.3.10 (excluding)
cpe:2.3:h:cisco:rv016_multi-wan_vpn:-:*:*:*:*:*:*:*
cpe:2.3:o:cisco:rv042_dual_wan_vpn_firmware:*:*:*:*:*:*:*:* 4.2.3.10 (excluding)
cpe:2.3:h:cisco:rv042_dual_wan_vpn:-:*:*:*:*:*:*:*
cpe:2.3:o:cisco:rv042g_dual_gigabit_wan_vpn_firmware:*:*:*:*:*:*:*:* 4.2.3.10 (excluding)
cpe:2.3:h:cisco:rv042g_dual_gigabit_wan_vpn:-:*:*:*:*:*:*:*
cpe:2.3:o:cisco:rv082_dual_wan_vpn_firmware:*:*:*:*:*:*:*:* 4.2.3.10 (excluding)
cpe:2.3:h:cisco:rv082_dual_wan_vpn:-:*:*:*:*:*:*:*